Re: Preview of changes to the Security susbystem for 2.6.36

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Valdis.Kletnieks
Date: Tuesday, August 3, 2010 - 11:18 pm

On Wed, 04 Aug 2010 12:54:32 +0900, Tetsuo Handa said:


I am unable to replicate this behavior on my system with SELinux set to
enforcing mode.  However, it does happen (which is to be expected) when SELinux
is set to permissive mode.

% rpm -q openssh selinux-policy-mls
openssh-5.5p1-18.fc14.x86_64
selinux-policy-mls-3.8.8-8.fc14.noarch

Tested by by trying both /etc/issue and /etc/shadow as banner files - in permissive
mode, both files would be displayed. In enforcing mode, /etc/issue would show
up and /etc/shadow would not.  In addition, checking of the actual policy
source for ssh shows no entry for auth_read_shadow() for sshd_t, although it is
present for many other systemd daemons that have a need to read it. So in
enforcing mode, there's no rule allowing sshd to open /etc/shadow, so it won't
open.

Are you sure you weren't running in permissive mode when you tested this?
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Preview of changes to the Security susbystem for 2.6.36, James Morris, (Fri Jul 30, 1:59 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Mon Aug 2, 3:19 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christoph Hellwig, (Mon Aug 2, 5:24 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Serge E. Hallyn, (Mon Aug 2, 11:08 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Mon Aug 2, 11:50 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Mon Aug 2, 11:51 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 2:38 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Tue Aug 3, 2:52 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 7:07 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 11:18 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Wed Aug 4, 5:21 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Wed Aug 4, 9:23 am)